
Security Engineer — Application Security & Identity
Real Chemistry2 months ago
Remote, United States +3 moreMid Level / Senior
H1B Sponsor
Base Salary
$60k - $80k/yr
Responsibilities
- Conduct application security reviews covering data flows, security control design, secrets handling, and AI/LLM data loss prevention.
- Co-lead production readiness reviews through threat modeling, hardening validation, and compliance mapping.
- Define corporate and workload identity architecture using Entra ID, AWS IAM, and GitHub OIDC.
- Define and manage GitHub-native security controls including CodeQL, Dependabot, secret scanning, branch protection, and environment controls.
- Establish standards for SAST, SCA, container scanning, and infrastructure-as-code policy tooling.
- Define AWS security standards for IAM, least privilege, logging, auditing, and secrets management.
- Scope and coordinate third-party penetration testing.
- Maintain audit logging maturity, including baseline logging, user activity tracking, tamper-evident trails, and SIEM integration.
- Triage and classify critical intake issues involving data exposure, credentials, and regulatory risk within required timeframes.
- Partner with DevOps Engineering to implement security policies in pipelines and infrastructure.
- Define approved AI providers, prompt-data handling policies, human-in-the-loop requirements, and AI service spending guardrails.
Requirements
- At least 5 years of cloud security experience, or 3–5+ years in a high-growth environment, with 2 years focused on application security.
- Hands-on experience with AWS IAM, SAML/OIDC federation, and GitHub security tooling.
- Experience with threat modeling and coordinating penetration testing.
- Familiarity with SOC 2, GDPR, and HIPAA-adjacent controls.
- In-depth understanding of the security risk lifecycle.
- Preferred experience securing GitHub-based CI/CD pipelines and AWS-native environments.
- Preferred exposure to regulated industries and controls such as GxP and 21 CFR Part 11.
- Security certifications such as CISSP, CCSP, OSCP, or GIAC are preferred.
- An associate degree or higher is preferred.
- Experience bringing low-code or AI-generated applications under enterprise security controls is preferred.
Benefits
- Hybrid work from any listed U.S. office or remote within the U.S., depending on team and business needs.
- Employees within an hour of an office are expected to work in-office two days per week; other regional employees work remotely and meet quarterly.
- Generous holidays and paid time off.
- Private medical, dental, and vision plan options.
- Retirement savings support.
- Mental wellness coaching and support.
- Access to more than 13,000 LinkedIn Learning classes.
- Free snacks at key-market offices.
About Real Chemistry
Real Chemistry is a tier-one partner to the world's most innovative life sciences and healthcare companies. As a leading provider of AI-powered audience analytics and insights, Real Chemistry helps the healthcare industry better understand, reach and engage critical audiences to improve the healthcare experience for all. Anchored by our culture of innovation and creativity, Real Chemistry’s 2,400+ global experts across life sciences, marketing communications and technology are singularly focused on navigating the complexities of bringing scientific advances to market and, most importantly, to the people who need them.